How to improve email sender reputation with Amazon SES Email Validation

Post Syndicated from Zip Zieper original https://aws.amazon.com/blogs/messaging-and-targeting/how-to-improve-email-sender-reputation-with-amazon-ses-email-validation/

If you’re sending emails at scale with Amazon Simple Email Service (Amazon SES), maintaining high deliverability depends on more than the content you send. It’s about who receives those emails. Mailbox providers like Gmail, Yahoo, and Outlook assign reputation scores based on your sending practices, domain and IP authentication records, message quality, and recipient engagement. These providers use their own algorithms to decide whether your emails reach the inbox, are filtered as spam, or aren’t delivered at all. For more information about managing your email reputation, see The Four Pillars of Managing Email Reputation. In this post, we show you how the Amazon SES Email Validation feature can help you to protect your sender reputation.

The email bounce rate is the percentage of emails that fail to deliver and is one of the most critical factors affecting your sender reputation. Every bounce damages your sender reputation. Mailbox providers like Gmail and Outlook closely monitor bounce rates, and accounts that bounce over 5% trigger warnings. If your account bounce rate exceeds 10%, the email services providers might throttle, or completely block sending. For customers sending email at scale with Amazon SES, a high bounce rate may trigger immediate consequences: damaged sender reputation, blocked deliverability, and ISP penalties that can throttle or suspend your entire email program. Traditional approaches to email quality are reactive, because you will only discover problems after bounces have damaged your reputation. While account suppression lists protect against known problematic addresses, they can’t protect you from the normal decay of email address quality that occurs because of job changes, abandoned mailboxes, domain expirations, or bots and bad actors looking to damage your email reputation.

Use Amazon SES Email Validation to help you protect your sender reputation

Amazon SES Email Validation shifts bounce management from reactive to proactive, helping you detect problems before they damage your sender reputation. The feature provides two validation approaches: the Email Validation API for timely checks during registration and Auto Validation to automatically review all outbound email addresses before sending and only deliver messages to recipients that meet your selected validation threshold. Both methods are intended to catch problem addresses before they become bounces, helping to protect your sender reputation.

In this post, we guide you through implementing both validation approaches using AnyCompany—a fictitious ecommerce website—as our example. You will see how AnyCompany might use the Email Validation API for timely registration checks on address acquisition and Auto Validation at time of sending. You’ll learn how to protect your sender reputation proactively and integrate validation into existing workflows with minimal disruption. We also show you how to use Amazon CloudWatch metrics to improve email list health over time. After you’re done reading and experimenting, you’ll understand how Amazon SES Email Validation can help transform your email operations from reactive bounce management to proactive quality assurance.

Solution overview – how to use the Email Validation API to avoid ingesting invalid email addresses

You can use the Email Validation API to validate email addresses through synchronous API calls to check addresses at the point of collection. This method gives you immediate feedback about address validity and helps prevent invalid addresses from entering your database. You control when validation occurs and how to handle the results. The Email Validation API costs $0.01 per validation using the API or the AWS Management Console for Amazon SES. See Amazon SES pricing for details.

The Amazon SES console uses the Email Validation API to manually validate up to 10 email addresses at a time. The results are shown in the console—shown in the following screenshot—and you can export the results to a CSV file.

The Email Validate API can be used in your code or using the AWS Command Line Interface (AWS CLI) to validate individual email addresses through synchronous API calls. This method is well-suited for validating addresses at the point of collection—during user registration, subscription form submission, or during an email list import to help prevent invalid addresses from entering your database. The following is an example using the AWS CLI.

aws sesv2 get-email-address-insights \
    --email-address [email protected] \
    --region us-east-1

The API returns a response structure similar to the following example:

{
  "MailboxValidation": {
    "IsValid": {
      "ConfidenceVerdict": "HIGH"
    },
    "Evaluations": {
      "HasValidSyntax": {
        "ConfidenceVerdict": "HIGH"
      },
      "HasValidDnsRecords": {
        "ConfidenceVerdict": "MEDIUM"
      },
      "MailboxExists": {
        "ConfidenceVerdict": "MEDIUM"
      },
      "IsRoleAddress": {
        "ConfidenceVerdict": "LOW"
      },
      "IsDisposable": {
        "ConfidenceVerdict": "LOW"
      },
      "IsRandomInput": {
        "ConfidenceVerdict": "LOW"
      }
    }
  }
}

Understanding Email Validation API verdicts

For each email, the Email Validation API returns an overall validity confidence with three possible aggregate verdicts:

  • HIGH – The email address passed all critical validation checks and is highly likely to be deliverable. These addresses can be accepted without additional scrutiny.
  • MEDIUM – The email address passed basic validation but has characteristics that might affect deliverability (such as being a role address or having uncertain mailbox existence). Your use case and bounce risk tolerance should be used to determine whether to accept these addresses.
  • LOW – The email address failed one or more critical validation checks and is unlikely to be deliverable. Your use case and bounce risk tolerance will most likely cause you to reject these addresses.

To reach the overall validity confidence, the Email Validation API performs six detailed checks on each email address:

  • Syntax validation (HasValidSyntax) – Confirms the address follows RFC 5321 and RFC 5322 standards for email address formatting. This catches obvious errors such as missing @ symbols or invalid characters.
  • DNS verification (HasValidDnsRecords) – Validates that the domain exists and has proper mail exchange (MX) records and corresponding A records configured. This helps confirm that the domain can receive email.
  • Mailbox existence (MailboxExists) – Predicts whether the specific mailbox exists and can receive messages.
  • Role address detection (IsRoleAddress) – Identifies generic addresses like [email protected] or [email protected] that typically represent shared mailboxes rather than individual recipients.
  • Disposable email detection (IsDisposable) – Checks temporary email services like mailinator.com or guerrillamail.com that users often employ to avoid providing real contact information.
  • Random input detection (IsRandomInput) – Checks randomly generated patterns.

For more information about response values and data types, see the MailboxValidation data type in the Amazon SES API v2 reference.

The Email Validation API provides a dashboard in the Amazon SES console that you can use to view email address verification results over time, with the ability to look back for up to one month, as shown in the following screenshot.

Use auto validation to help prevent bounces when sending from Amazon SES

Amazon SES Auto Validation automatically performs comprehensive address validation through multiple checks such as syntax validation, DNS records, and others before each message is sent. When auto validation is enabled, Amazon SES will only deliver messages to recipients that meet your selected validation threshold. This helps you protect your sender reputation by preventing sends to addresses that have a high probability of being invalid or risky without requiring manual intervention or API integration. Auto Validation must be enabled separately for each AWS region in your account. For example, if you enable it in us-east-1, it will not be active in us-west-2 unless you explicitly enable it there as well. You can enable it at the account level for an entire region, or selectively within configuration sets. Auto validation costs $0.01 per 1,000 validations. Be aware that sends suppressed by Auto Validation count towards your daily send quota, and you will be charged the standard outgoing message fee for suppressed sends (in addition to the fee for auto validation). See Amazon SES pricing for more information.

When enabled at the AWS account level, you set the Validation threshold to determine which email addresses to suppress based on their validity confidence, as shown in the following screenshot.

  • Amazon SES managed threshold (recommended) – Amazon SES automatically manages the threshold to suppress invalid addresses based on your sending patterns and reputation. This option allows Amazon SES to optimize the validation threshold dynamically. Use this threshold when you want AWS to handle validation decisions based on your account’s specific characteristics.
  • Custom threshold –
    • High – Delivers emails only to addresses with high delivery likelihood. This provides maximum protection for your sender reputation but might suppress some legitimate addresses with medium delivery confidence. Use this threshold for critical transactional emails or when protecting sender reputation is your top priority.
    • Medium – Delivers emails to addresses with medium or high delivery likelihood. This balances reputation protection with delivery reach by allowing addresses with moderate deliverability scores. Use this threshold for marketing campaigns where you want to maximize reach while still filtering obviously invalid addresses.

You will usually find that using the recommended Amazon SES managed threshold works best for the bulk of your sending, however for certain use cases you might want to override the account setting and use a custom threshold in your configuration set. If you choose High or Medium thresholds instead of Amazon SES managed (as shown in the following screenshot), it’s important that you monitor your delivery metrics and validation results regularly.

Auto Validation applies to all outbound emails sent through your account. Addresses that don’t meet your threshold will be suppressed with the bounceSubType of EmailValidationSuppressed. Suppressed sends count towards your daily send quota, and you will be charged the standard outgoing message fee for suppressed sends in addition to the fee for auto validation.

{
  "Type": "Notification",
  "MessageId": "0ded6fd6-4e59-5ae0-9782-0e68faa886e7",
  "TopicArn": "arn:aws:sns:us-east-1:252640393490:ses-auto-validate",
  "Subject": "Amazon SES Email Event Notification",
  "Message": "{\"**eventType**\":\"**Bounce**\",\"bounce\":{\"feedbackId\":\"0100019b345a05a0-95e3062a-9594-499f-aafc-dc2dc9647cb6-000000\",\"**bounceType**\":\"**Permanent**\",\"**bounceSubType**\":\"**EmailValidationSuppressed**\",\"bouncedRecipients\":"
}

How AnyCompany might use the Email Validation API and auto validation

AnyCompany runs an ecommerce platform for both business and consumer office supplies. The company’s website hosts various web-forms for customers to create accounts and sign up to receive newsletters and discount offers. When they place orders through the platform, AnyCompany’s system sends order confirmations and delivery tracking emails. Today, when a new user registers through one of the web forms, AnyCompany sends a verification email to confirm the user’s email address, contact details, and opt-in to the company’s emails. If a user misspells their email address, they will never receive this verification email. Frustrated, they might move on to another provider. Similarly, if a bot or bad actor deliberately submits invalid addresses to the web form, verification emails will bounce. Both scenarios cost AnyCompany money with no return; at scale, a high bounce rate might cause email service providers to throttle or block future sends. AnyCompany previously investigated various third-party email validation services, but the engineering work, security reviews, and costs outweighed the expected benefits. This necessitated the cloud team’s constant and careful vigilance over the company’s bounce rate and reputation, diverting resources that the company would prefer to deploy elsewhere. As an ecommerce company, AnyCompany needs to be highly protective of its sender reputation. With email validation now built directly into Amazon SES, AnyCompany can bypass the complexity and cost of third-party tools and directly benefit from proactive bounce prevention across all email use cases. In the following section, we guide you through the simple steps AnyCompany might take to implement Amazon SES Email Validation.

Prerequisites

Before implementing Email Validation, you’ll need:

AWS account :

  • An AWS account with Amazon SES enabled in your desired AWS Region
  • AWS CLI version 2.0 or later installed and configured

Required IAM permissions:

Your IAM user or role needs the following permissions to configure Email Validation:

  • ses:PutAccountSuppressionAttributes – To enable and configure Email Validation at the account level
  • ses:GetAccount to verify Email Validation configuration
  • ses:CreateConfigurationSet when creating a new configuration set
  • ses:PutConfigurationSetSuppressionOptionsto override validation settings for specific configuration sets
  • ses:GetEmailAddressInsights to call the Email Validation API
  • iam:CreateServiceLinkedRole  creates an IAM service-linked role that is used by Amazon SES to publish CloudWatch metrics
  • cloudwatch:GetMetricStatistics – To retrieve validation metrics

Development environment:

  • Familiarity with AWS CLI commands and JSON configuration files
  • For API integration, SDK support for Amazon SES API v2 in your preferred programming language
  • Access to your application’s user registration code

Existing Amazon SES configuration:

  • At least one verified email address or domain in Amazon SES

While the Email Validation API works with an AWS account that is in the Amazon SES sandbox, auto validation is best demonstrated after your AWS account has been granted production access.

  • (Optional) Configuration sets created for different email types (transactional, marketing, and so on)

Validating email addresses at acquisition with the Email Validation API

To prevent bad addresses from entering their customer database at time of acquisition, AnyCompany will integrate the Email Validation API directly into their registration form. When a user submits their contact details, including email address, the Email Validation API is used. Results arrive within 100 milliseconds, with the overall validity confidence and six detailed checks of the email address. AnyCompany will then use the results and custom business logic they designed for their different use cases. For example, for their B2B business, they might allow registrations with high overall confidences and a role address, such as [email protected]. For the consumer business, they might accept registrations with medium overall confidences, but always reject emails that the API identifies as disposable, such as [email protected] or random, such as [email protected].

Sample code snippets

The code snippets in this section are examples only and are not intended for production use.

Step 1: Validate email address on form submission

When a user submits the registration form, AnyCompany’s application calls the Email Validation API before creating the account:

import boto3

ses_client = boto3.client('sesv2', region_name='us-east-1')

def validate_registration_email(email_address):
    try:
        response = ses_client.get_email_address_insights(
            EmailAddress=email_address
        )
        return response
    except Exception as e:
        # Handle API errors gracefully
        print(f"Validation error: {e}")
        return None

Step 2: Apply business rules based on verdict

AnyCompany’s business logic handles different validation outcomes:

def should_accept_email(validation_response, registration_type):
    if not validation_response:
        # API error - accept email but flag for manual review
        return True, "accepted_with_warning"

    overall_verdict = validation_response['MailboxValidation']['IsValid']['ConfidenceVerdict']
    checks = validation_response['MailboxValidation']['Evaluations']

    # Always reject FAIL verdicts
    if overall_verdict == 'LOW':
        return False, "rejected_invalid"

    # Always accept PASS verdicts
    if overall_verdict == 'HIGH':
        return True, "accepted"

    # Handle NEUTRAL verdicts based on registration type
    if overall_verdict == 'MEDIUM':
        # Reject disposable emails for all registration types
        if checks['IsDisposable']['ConfidenceVerdict'] == 'HIGH':
            return False, "rejected_disposable"

        # Accept role addresses for B2B, reject for consumer
        if checks['IsRoleAddress']['ConfidenceVerdict'] == 'HIGH':
            if registration_type == 'b2b':
                return True, "accepted_role_address"
            else:
                return False, "rejected_role_address"

        # Accept other NEUTRAL cases with warning
        return True, "accepted_with_warning"

Step 3: Provide user-friendly error messages

When validation fails, AnyCompany provides specific, actionable feedback (you can add more conditions based on your requirements):

def get_user_error_message(validation_response):
    checks = validation_response['Evaluations']

    if checks['HasValidSyntax']['ConfidenceVerdict'] == 'LOW':
        return "Please check your email address for typos. It appears to have formatting errors."

    if checks['HasValidDnsRecords']['ConfidenceVerdict'] == 'LOW':
        return "The domain in your email address doesn't appear to exist. Please verify you entered it correctly."

    if checks['IsDisposable']['ConfidenceVerdict'] == 'HIGH':
        return "Temporary email addresses are not accepted. Please use a different email address."

    if checks['IsRoleAddress']['ConfidenceVerdict'] == 'HIGH':
        return "Please use a personal email address rather than a shared mailbox like support@ or admin@."

    return "We couldn't verify this email address. Please check for typos and try again."

Step 4: Suggest corrections for common mistakes

For addresses that fail DNS validation, AnyCompany suggests common corrections to popular domain typos.

def suggest_email_correction(email_address):
    common_domains = {
        'gmial.com': 'gmail.com',
        'gmai.com': 'gmail.com',
        'yahooo.com': 'yahoo.com',
        'hotmial.com': 'hotmail.com',
        'outlok.com': 'outlook.com'
    }

    # Extract domain from email
    if '@' in email_address:
        local, domain = email_address.split('@', 1)

        # Check for common misspellings
        if domain.lower() in common_domains:
            suggested_domain = common_domains[domain.lower()]
            return f"{local}@{suggested_domain}"

    return None

Key benefits of the Email Validation API

The Email Validation API provide proactive quality control by preventing invalid addresses from entering AnyCompany’s database, preventing the reputation damage that occurs when they send to addresses that bounce.

  • Immediate user feedback – Because validation results return within milliseconds, AnyCompany can provide real-time feedback during registration without impacting user experience.
  • Flexible policy enforcement – AnyCompany can use individual check results to define custom validation policies that match their various business requirements, accepting or rejecting addresses based on use case-specific risk tolerance.
  • Cost-effective validation – AnyCompany pays only for the addresses they validate, with no infrastructure to provision or manage and no license fees. Preventing a single bounce might save more than the cost of validation.

By integrating the Email Validation API into their registration workflow, AnyCompany can transform their approach from reactive bounce management to proactive quality assurance. Invalid addresses are prevented from entering their database, legitimate customers receive verification emails reliably, and their sender reputation remains protected with little to no ongoing effort.

Set up a CloudWatch alarm for high rates of LOW verdicts

You can configure CloudWatch alarms to notify you when validation patterns indicate a consistently high rate of LOW verdicts. This might indicate malicious bots attempting to sign up through a web-form or other mechanism.

The following example creates a CloudWatch alarm that fires when the rate of LOW verdicts exceeds 20%.

aws cloudwatch put-metric-alarm \
  --region us-east-1 \
  --alarm-name "EmailInsights-LOW-Rate-Above-20-Percent" \
  --alarm-description "Alarm when LOW confidence verdict rate exceeds 20%" \
  --comparison-operator GreaterThanThreshold \
  --threshold 20 \
  --evaluation-periods 2 \
  --treat-missing-data notBreaching \
  --metrics '[
    {
      "Id": "low",
      "MetricStat": {
        "Metric": {
          "MetricName": "EmailAddressInsights.ConfidenceVerdict.LOW",
          "Namespace": "AWS/SES"
        },
        "Period": 300,
        "Stat": "Sum"
      },
      "ReturnData": false
    },
    {
      "Id": "medium",
      "MetricStat": {
        "Metric": {
          "MetricName": "EmailAddressInsights.ConfidenceVerdict.MEDIUM",
          "Namespace": "AWS/SES"
        },
        "Period": 300,
        "Stat": "Sum"
      },
      "ReturnData": false
    },
    {
      "Id": "high",
      "MetricStat": {
        "Metric": {
          "MetricName": "EmailAddressInsights.ConfidenceVerdict.HIGH",
          "Namespace": "AWS/SES"
        },
        "Period": 300,
        "Stat": "Sum"
      },
      "ReturnData": false
    },
    {
      "Id": "e1",
      "Expression": "IF((low+medium+high)>0, low/(low+medium+high)*100, 0)",
      "Label": "LOW Rate Percentage",
      "ReturnData": true
    }
  ]'

How AnyCompany uses validation metrics

AnyCompany monitors their Email Validation dashboard in the Amazon SES console to track list quality trends. For example, if they notice an increase in disposable email failures, they can add additional client-side validation to their registration forms to discourage this behavior. When Auto Validation blocks a spike of invalid addresses from a specific partner marketing campaign, they avoid the problems associated with a spike in bounces while being better informed when investigating the list source and removing or cleaning it for future campaigns.

Validating email addresses at send time with Auto Validation

AnyCompany has been operating its online platform for many years without a way to validate email addresses. The company also makes frequent acquisitions and partnerships that regularly introduce new email addresses into their sending. This means that no matter how well the new registration for with the Email Validation API performs, they will always have some invalid email addresses in their outbound sends.

This is one of the scenarios that can be addressed with no code or process changes by using Auto Validation. When enabled at the AWS account level, Auto Validation checks each address before sending, automatically suppressing the send of invalid addresses, adding those addresses to the account suppression list, and generating bounce notification events. These bounce events appear in Amazon SES event publishing and can be monitored using Amazon CloudWatch, Amazon Simple Notification Service (Amazon SNS), or Amazon EventBridge or written to an Amazon Simple Storage Service (Amazon S3) bucket. Auto Validation bounce events appear as:

  • Bounce type: Permanent for addresses that will never be deliverable
  • Bounce subtype: EmailValidationSuppressed indicating Auto Validation blocked the send

Because it’s implemented in Amazon SES events, AnyCompany can handle address validation failures the same way they currently handle actual bounces from mailbox providers, maintaining consistency in their email processing workflows.

Conclusion

Amazon SES Email Validation addresses critical needs for organizations sending email at scale: preventing invalid addresses at registration and automatically filtering risky recipients before sending. The feature’s two complementary approaches—the Email Validation API for real-time checks and Auto Validation for automatic send-time filtering—give you flexibility to implement validation where it makes the most sense for your workflows.

Use the Email Validation API to:

  • Validate at point of collection (registration, imports)
  • Receive immediate user feedback
  • Build custom validation workflows
  • Validate before database entry
  • Validate up to 10 addresses

Use Auto Validation to:

  • Automatically protect ongoing campaigns automatically
  • Avoid code changes to sending logic
  • Provide consistent quality across all sends
  • Set organization-wide quality standards

By implementing both features of Amazon SES Email Validation, you can better protect your sender reputation by proactively preventing bounces, reducing the possibility of high bounce rates that can damage your deliverability.

Next steps

Start improving your email deliverability today:

  1. Enable Email Validation in your AWS account using the Amazon SES console or the AWS CLI
  2. Implement API validation at your registration points to improve data quality from the start
  3. Configure Auto Validation policies to protect your sender reputation across all campaigns
  4. Set up CloudWatch dashboards to track validation performance and identify list quality trends
  5. Review validation metrics weekly to refine your validation policies based on actual patterns

For more information about Amazon SES Email Validation, see the Amazon SES Developer Guide.


About the authors

AI and the Corporate Capture of Knowledge

Post Syndicated from Bruce Schneier original https://www.schneier.com/blog/archives/2026/01/ai-and-the-corporate-capture-of-knowledge.html

More than a decade after Aaron Swartz’s death, the United States is still living inside the contradiction that destroyed him.

Swartz believed that knowledge, especially publicly funded knowledge, should be freely accessible. Acting on that, he downloaded thousands of academic articles from the JSTOR archive with the intention of making them publicly available. For this, the federal government charged him with a felony and threatened decades in prison. After two years of prosecutorial pressure, Swartz died by suicide on Jan. 11, 2013.

The still-unresolved questions raised by his case have resurfaced in today’s debates over artificial intelligence, copyright and the ultimate control of knowledge.

At the time of Swartz’s prosecution, vast amounts of research were funded by taxpayers, conducted at public institutions and intended to advance public understanding. But access to that research was, and still is, locked behind expensive paywalls. People are unable to read work they helped fund without paying private journals and research websites.

Swartz considered this hoarding of knowledge to be neither accidental nor inevitable. It was the result of legal, economic and political choices. His actions challenged those choices directly. And for that, the government treated him as a criminal.

Today’s AI arms race involves a far more expansive, profit-driven form of information appropriation. The tech giants ingest vast amounts of copyrighted material: books, journalism, academic papers, art, music and personal writing. This data is scraped at industrial scale, often without consent, compensation or transparency, and then used to train large AI models.

AI companies then sell their proprietary systems, built on public and private knowledge, back to the people who funded it. But this time, the government’s response has been markedly different. There are no criminal prosecutions, no threats of decades-long prison sentences. Lawsuits proceed slowly, enforcement remains uncertain and policymakers signal caution, given AI’s perceived economic and strategic importance. Copyright infringement is reframed as an unfortunate but necessary step toward “innovation.”

Recent developments underscore this imbalance. In 2025, Anthropic reached a settlement with publishers over allegations that its AI systems were trained on copyrighted books without authorization. The agreement reportedly valued infringement at roughly $3,000 per book across an estimated 500,000 works, coming at a cost of over $1.5 billion. Plagiarism disputes between artists and accused infringers routinely settle for hundreds of thousands, or even millions, of dollars when prominent works are involved. Scholars estimate Anthropic avoided over $1 trillion in liability costs. For well-capitalized AI firms, such settlements are likely being factored as a predictable cost of doing business.

As AI becomes a larger part of America’s economy, one can see the writing on the wall. Judges will twist themselves into knots to justify an innovative technology premised on literally stealing the works of artists, poets, musicians, all of academia and the internet, and vast expanses of literature. But if Swartz’s actions were criminal, it is worth asking: What standard are we now applying to AI companies?

The question is not simply whether copyright law applies to AI. It is why the law appears to operate so differently depending on who is doing the extracting and for what purpose.

The stakes extend beyond copyright law or past injustices. They concern who controls the infrastructure of knowledge going forward and what that control means for democratic participation, accountability and public trust.

Systems trained on vast bodies of publicly funded research are increasingly becoming the primary way people learn about science, law, medicine and public policy. As search, synthesis and explanation are mediated through AI models, control over training data and infrastructure translates into control over what questions can be asked, what answers are surfaced, and whose expertise is treated as authoritative. If public knowledge is absorbed into proprietary systems that the public cannot inspect, audit or meaningfully challenge, then access to information is no longer governed by democratic norms but by corporate priorities.

Like the early internet, AI is often described as a democratizing force. But also like the internet, AI’s current trajectory suggests something closer to consolidation. Control over data, models and computational infrastructure is concentrated in the hands of a small number of powerful tech companies. They will decide who gets access to knowledge, under what conditions and at what price.

Swartz’s fight was not simply about access, but about whether knowledge should be governed by openness or corporate capture, and who that knowledge is ultimately for. He understood that access to knowledge is a prerequisite for democracy. A society cannot meaningfully debate policy, science or justice if information is locked away behind paywalls or controlled by proprietary algorithms. If we allow AI companies to profit from mass appropriation while claiming immunity, we are choosing a future in which access to knowledge is governed by corporate power rather than democratic values.

How we treat knowledge—who may access it, who may profit from it and who is punished for sharing it—has become a test of our democratic commitments. We should be honest about what those choices say about us.

This essay was written with J. B. Branch, and originally appeared in the San Francisco Chronicle.

Security updates for Friday

Post Syndicated from jzb original https://lwn.net/Articles/1054683/

Security updates have been issued by AlmaLinux (gnupg2), Debian (firefox-esr), Oracle (cups, gnupg2, libpq, net-snmp, postgresql, postgresql:15, postgresql:16, transfig, and vsftpd), Red Hat (firefox), SUSE (apache2, curl, firefox, gpg2, hawk2, libcryptopp-devel, openCryptoki, python310, python311-urllib3, rke2, squid, and tomcat), and Ubuntu (cpp-httplib, git, python-apt, and simgear).

Astro is joining Cloudflare

Post Syndicated from Fred Schott original https://blog.cloudflare.com/astro-joins-cloudflare/

The Astro Technology Company, creators of the Astro web framework, is joining Cloudflare.

Astro is the web framework for building fast, content-driven websites. Over the past few years, we’ve seen an incredibly diverse range of developers and companies use Astro to build for the web. This ranges from established brands like Porsche and IKEA, to fast-growing AI companies like Opencode and OpenAI. Platforms that are built on Cloudflare, like Webflow Cloud and Wix Vibe, have chosen Astro to power the websites their customers build and deploy to their own platforms. At Cloudflare, we use Astro, too — for our developer docs, website, landing pages, and more. Astro is used almost everywhere there is content on the Internet.

By joining forces with the Astro team, we are doubling down on making Astro the best framework for content-driven websites for many years to come. The best version of Astro — Astro 6 —  is just around the corner, bringing a redesigned development server powered by Vite. The first public beta release of Astro 6 is now available, with GA coming in the weeks ahead.

We are excited to share this news and even more thrilled for what it means for developers building with Astro. If you haven’t yet tried Astro — give it a spin and run npm create astro@latest.

What this means for Astro

Astro will remain open source, MIT-licensed, and open to contributions, with a public roadmap and open governance. All full-time employees of The Astro Technology Company are now employees of Cloudflare, and will continue to work on Astro. We’re committed to Astro’s long-term success and eager to keep building.

Astro wouldn’t be what it is today without an incredibly strong community of open-source contributors. Cloudflare is also committed to continuing to support open-source contributions, via the Astro Ecosystem Fund, alongside industry partners including Webflow, Netlify, Wix, Sentry, Stainless and many more.

From day one, Astro has been a bet on the web and portability: Astro is built to run anywhere, across clouds and platforms. Nothing changes about that. You can deploy Astro to any platform or cloud, and we’re committed to supporting Astro developers everywhere.

There are many web frameworks out there — so why are developers choosing Astro?

Astro has been growing rapidly:


Why? Many web frameworks have come and gone trying to be everything to everyone, aiming to serve the needs of both content-driven websites and web applications.

The key to Astro’s success: Instead of trying to serve every use case, Astro has stayed focused on five design principles. Astro is…

  • Content-driven: Astro was designed to showcase your content.

  • Server-first: Websites run faster when they render HTML on the server.

  • Fast by default: It should be impossible to build a slow website in Astro.

  • Easy to use: You don’t need to be an expert to build something with Astro.

  • Developer-focused: You should have the resources you need to be successful.

Astro’s Islands Architecture is a core part of what makes all of this possible. The majority of each page can be fast, static HTML — fast and simple to build by default, oriented around rendering content. And when you need it, you can render a specific part of a page as a client island, using any client UI framework. You can even mix and match multiple frameworks on the same page, whether that’s React.js, Vue, Svelte, Solid, or anything else:


Bringing back the joy in building websites

The more Astro and Cloudflare started talking, the clearer it became how much we have in common. Cloudflare’s mission is to help build a better Internet — and part of that is to help build a faster Internet. Almost all of us grew up building websites, and we want a world where people have fun building things on the Internet, where anyone can publish to a site that is truly their own.

When Astro first launched in 2021, it had become painful to build great websites — it felt like a fight with build tools and frameworks. It sounds strange to say it, with the coding agents and powerful LLMs of 2026, but in 2021 it was very hard to build an excellent and fast website without being a domain expert in JavaScript build tooling. So much has gotten better, both because of Astro and in the broader frontend ecosystem, that we take this almost for granted today.

The Astro project has spent the past five years working to simplify web development. So as LLMs, then vibe coding, and now true coding agents have come along and made it possible for truly anyone to build — Astro provided a foundation that was simple and fast by default. We’ve all seen how much better and faster agents get when building off the right foundation, in a well-structured codebase. More and more, we’ve seen both builders and platforms choose Astro as that foundation.

We’ve seen this most clearly through the platforms that both Cloudflare and Astro serve, that extend Cloudflare to their own customers in creative ways using Cloudflare for Platforms, and have chosen Astro as the framework that their customers build on. 

When you deploy to Webflow Cloud, your Astro site just works and is deployed across Cloudflare’s network. When you start a new project with Wix Vibe, behind the scenes you’re creating an Astro site, running on Cloudflare. And when you generate a developer docs site using Stainless, that generates an Astro project, running on Cloudflare, powered by Starlight — a framework built on Astro.

Each of these platforms is built for a different audience. But what they have in common — beyond their use of Cloudflare and Astro — is they make it fun to create and publish content to the Internet. In a world where everyone can be both a builder and content creator, we think there are still so many more platforms to build and people to reach.

Astro 6 — new local dev server, powered by Vite

Astro 6 is coming, and the first open beta release is now available. To be one of the first to try it out, run:

npm create astro@latest -- --ref next

Or to upgrade your existing Astro app, run:

npx @astrojs/upgrade beta

Astro 6 brings a brand new development server, built on the Vite Environments API, that runs your code locally using the same runtime that you deploy to. This means that when you run astro dev with the Cloudflare Vite plugin, your code runs in workerd, the open-source Cloudflare Workers runtime, and can use Durable Objects, D1, KV, Agents and more. This isn’t just a Cloudflare feature: Any JavaScript runtime with a plugin that uses the Vite Environments API can benefit from this new support, and ensure local dev runs in the same environment, with the same runtime APIs as production.


Live Content Collections in Astro are also stable in Astro 6 and out of beta. These content collections let you update data in real time, without requiring a rebuild of your site. This makes it easy to bring in content that changes often, such as the current inventory in a storefront, while still benefitting from the built-in validation and caching that come with Astro’s existing support for content collections.

There’s more to Astro 6, including Astro’s most upvoted feature request — first-class support for Content Security Policy (CSP) — as well as simpler APIs, an upgrade to Zod 4, and more.

Doubling down on Astro

We’re thrilled to welcome the Astro team to Cloudflare. We’re excited to keep building, keep shipping, and keep making Astro the best way to build content-driven sites. We’re already thinking about what comes next beyond V6, and we’d love to hear from you.

To keep up with the latest, follow the Astro blog and join the Astro Discord. Tell us what you’re building!

На второ четене: „Речник на войната“

Post Syndicated from Стефан Иванов original https://www.toest.bg/na-vtoro-chetene-rechnik-na-voynata-ot-ostap-slivinski/

„Речник на войната“ от Остап Сливински

На второ четене: „Речник на войната“

превод от украински Райна Камберова, Пловдив: изд. „Жанет 45“, 2024

Още малко остава до четиригодишнината от началото на войната на Русия в Украйна. Това прави тази книга още по-болезнена и важна. Тя флиртува опасно с автопародията на своята форма. Представете си речник, една от най-авторитарните текстови конструкции, наследник на просвещенската мания за категоризация, който внезапно признава собствената си импотентност. Ако Дидро и Д’Аламбер вярваха, че светът може да бъде картографиран и овладян чрез азбучен ред, то Сливински използва същата азбука, за да покаже как войната превръща всеки опит за ред в гротеска. Това не е деконструкция на жанра. Това е използване на скелета на Просвещението, за да се покаже разложението му.

Паралелите тук са множество и заплетени. На ум ни идва „Хазарски речник“ на Павич, но без магическия реализъм и със значително повече кръв. Припомняме си и Амброуз Биърс с неговия „Речник на дявола“, но докато при Биърс цинизмът е естетически избор, при Сливински той е физиологична необходимост. По-близо е дори до Бартовите „Митологии“, но с тази разлика, че тук демистификацията не е интелектуален жест, а екзистенциален императив.

Войната не ти позволява лукса на теоретизирането. Тя иска свидетелство, а не анализ.

Интересното е, че Сливински прави нещо още по-радикално от Милош или от късния Целан с неговата разпадната реч. Той не се опитва да върне думите към тяхната т.нар. „истинска“ етимологична чистота, нито да създаде нов травматичен език. Вместо това авторът показва как обикновеният език, с който пазаруваме, ругаем се едни други и флиртуваме, се деформира под натиска на историята. Балсамът остава балсам, но вече е и нещо друго. Той се превръща в обещание за цивилизация, носталгия по нормалността, почти метафизичен конструкт. Това е странно близко до феноменологията на Хайдегер, но изчистена от философския патос и пренесена в контекста на пазара на дребно в обсадения Мариупол.

Ако Толстой вярваше, че истината на войната може да бъде разказана чрез панорамното преплитане на индивидуалното с историческото, то Сливински демонстрира, че след Аушвиц, след Камбоджа, след Сребреница, след Алепо тази вяра е станала невъзможна. „Речник на войната“ е изграден от фрагменти, които упорито отказват да се съберат в мозайка. Няма цялост, защото целостта е лъжа. Има само осколки. Баба, легнала върху краката на непознат, за да го стопли. Котарак, чието оцеляване поставя неудобни морални въпроси. Билет за влак, който вече няма накъде да тръгне.

Тази стратегия неизбежно напомня документалния полифонизъм на Светлана Алексиевич, но с критична разлика. При Алексиевич има редакторски жест, има организиращ принцип, има и известна драматургия на монтажа. При Сливински има нещо по-близо до палимпсеста или до археологическите разкопки. Различните слоеве на преживяванията, които не са йерархизирани, не са и подредени по важност. Котаракът е също толкова значим, колкото и обстрелът, защото и двете неща са елементи от същата екзистенциална реалност, където границата между тривиалното и трагичното е безнадеждно замъглена.

Този подход има неочаквани родства с това, което Зебалд прави в „Аустерлиц“. Пътуването през паметта като блуждаене из руини, където случайният детайл изведнъж разкрива бездна. Или с късната проза на Кафка, където всекидневието е абсурдно не защото е сюрреалистично, а защото е твърде реално. При Сливински войната не е метафора. Тя си е съвсем буквална реалност, която обаче звучи толкова абсурдно, че почти изглежда като метафора. Жена с насапунисан гръб, евакуирана по средата на къпането си. Това е едновременно комично и ужасяващо и точно в този парадокс се крие истината, която героичният разказ винаги цензурира.

На второ четене: „Речник на войната“

Едно от най-силните постижения на книгата е начинът, по който предметният свят придобива почти теологична тежест. Банята, лампата, тиксото, ключовете вече не са реквизит на войната, а последните острови на смисъла в океан от хаос. Тук Сливински е удивително близо до хайдегеровското разбиране за das Zeug, онова подръчно битие на предметите, което става видимо едва когато се счупи техният инструментален статус. Както става и при Дон ДеЛило, когато супермаркетът, колата или боклукът са пространства на дълбинна тревога.

Но за разлика от ДеЛило, при когото капитализмът произвежда излишък от значения и всичко е знак, всичко е симулакрум, при Сливински имаме обратната ситуация, защото предметите внезапно престават да бъдат излишни. Топлата вода не е удобство, тя става чудо. Тиксото върху прозореца не е временна мярка, то се превръща в новата коледна звезда и в символ на въображаемата сигурност. Това е свят, в който IKEA естетиката на заменимостта се сблъсква с бруталната житейска необходимост. Всеки предмет може да бъде последният, затова всеки предмет внезапно става свещен.

Сливински е по-скептичен, неговите предмети не гарантират приемственост, те само свидетелстват за нейното отсъствие. Балсамът няма да върне миналото, той може само да намекне за него. Въпросът внезапно е не дали предметите ще бъдат запазени, а дали предметите ще запазят хората.

Войната в Речника се случва не само в пространството, но и във времето. Тя деформира самата му текстура. Календарът престава да подрежда, минутите се точат различно в зависимост от това дали чакаш сирената, или чакаш вода. Това не е психологическо наблюдение, това е промяна в битието. Времето на войната е по-близо до бекетовското циклене на едно място, но без абсурдистката дистанция. Тук никой не си задава въпроси за смисъла на чакането. Само чакаш и това чакане те изяжда отвътре.

В този аспект книгата неочаквано резонира с нашето собствено, уж мирно настояще. И ние живеем в парадоксална темпоралност. Перманентна криза, която никога не кулминира и никога не свършва. Новинарският цикъл, социалните мрежи, политическите скандали. Всичко е едновременно спешно и безкрайно повтарящо се. Войната в Украйна има това „предимство“, ако смеем да употребим думата – тя поне е истинска. Нашата тревожност е по-двусмислена, по-разпръсната, по-трудна за назоваване. Но механизмът е сходен. Времето престава да бъде субстанция в развитие и става гъста и лепкава среда, през която едва се движим.

Когато четем „Речник на войната“ от България, възниква странен ефект на удвояване. От една страна, има го комфорта на дистанцията. Това е там, това са другите, това не сме (засега) ние. От друга страна, езиковата и моралната криза, които книгата описва, звучат неприятно познато. И ние живеем в общество, където думи като свобода, справедливост и солидарност са толкова износени, че почти са станали неупотребими. И ние имаме собствени убежища, но не от бомби, а от реалност, от отговорност и от необходимостта да мислим.

Паралелът не е директен, но е възможен. Сливински показва свят, в който избор вече няма. В България изборът все още съществува, но все по-често изглежда илюзорен. Можем да откажем да избираме между партии, които ни лъжат.

Можем да не сме потребители на медии, които ни манипулират. Можем да изберем да вярваме в бъдеще, което може и да не дойде. Това не е травма в украинския смисъл, но е хронична анемия на смисъла.

И когато четем как в Мариупол някой открива балсам и го преживява като епифания, осъзнаваме колко често ние третираме собственото си нормално като нещо дължимо, досадно, че даже и недостатъчно.

Има и втори пласт на сравнението. България често се мисли като преддверие на Европа, на модерността и на катастрофата. Винаги сме „на път да“, „на ръба на“, „пред възможността за“. Тази позиция произвежда специфична среда на отлагането и на симулацията. Речникът показва свят, в който репетициите са свършили. Войната не е възможна, нито е заплаха, тя е започнала. И четейки това, можем да си зададем неудобния въпрос какво от нашето „нормално“ всъщност е само репетиция? Какво би оцеляло, ако утре трябваше да бъде истинско?

В крайна сметка „Речник на войната“ не предлага решения, защото решенията принадлежат на рационалния свят. Войната е пробив на ирационалното в ежедневието. Книгата прави нещо по-скромно и по-трудно. Тя настоява. Настоява думите да означават нещо дори когато е по-лесно да се изпразнят от смисъл. Настоява телата да бъдат видими дори когато статистиката ги прави призрачни. Настоява настоящето и миналото да не станат исторически твърде бързо, защото това е първата форма на забрава.

Ако има някакво послание в тази книга, а не съм сигурен, че го има или че би трябвало да го има, то е, че

езикът е последното бойно поле.

След като градовете са паднали, след като институциите са рухнали, след като идентичностите са разбити, остава още въпросът как ще говорим за това. И отговорът на Сливински е едновременно прост и радикален. Ще говорим внимателно, болезнено и честно. Ще говорим така, сякаш думите тежат. Защото тежат.

А за нас, които четем това отвън, остава въпросът готови ли сме да признаем, че нашите думи също са станали леки? Че нашето „нормално“ също е крехко? Че и нашият речник може един ден да се нуждае от преписване? „Речник на войната“ не ни дава отговори. Но ни задава въпроси, които е по-удобно да не си задаваме. И може би точно това го прави необходим.


Никой от нас не чете единствено най-новите книги. Тогава защо само за тях се пише? „На второ четене“ е рубрика, в която отваряме списъците с книги, публикувани преди поне година, четем ги и препоръчваме любимите си от тях. За нея медията „Тоест“ е отличена с Националната награда „Христо Г. Данов“ (2025) за принос в представянето на българската книга.

Рубриката е част от партньорската програма Читателски клуб „Тоест“, благодарение на която активните дарители на „Тоест“ получават 20% отстъпка от коричната цена на всички книги на включените издателства. Изборът на заглавия обаче е единствено на авторите Стефан Иванов, Севда Семер и Антония Апостолова, които биха ви препоръчали тези книги и ако имаше как да се разходите с тях в книжарницата. 

В броячите е силата. Не, в гражданите

Post Syndicated from Емилия Милчева original https://www.toest.bg/v-broyachite-e-silata-ne-v-grazhdanite/

Бюлетините не определят резултатите от изборите. Преброителите определят резултата. 

В броячите е силата. Не, в гражданите

Тази фраза принадлежи на американския политик Уилям Туид – Боса, известен и като Бос Туид, шефа на „политическата машина“ „Тамани Хол“. 

Католическата организация на практика управлява Демократическата партия в Ню Йорк и контролира изборите по времето на Позлатената епоха, но също така прибира милиони долари чрез измами, подкупи и контрол над обществени поръчки. С част от тези средства подкупва и съдии за решения в своя полза. Големи обществени проекти, като болници и пътища, пищни музеи, съдилища, дори Бруклинския мост, са с доста завишени разходи, а разликата отива при Туид и неговите приближени. Например тогавашната Съдебна палата, първоначално планирана за 250 000 долара, струва над 13 млн. долара, без да е завършена, и цялата разлика е усвоена от обръчите на Туид, т.нар. Τweed Ring.

Заради корупцията, машинациите и манипулациите на избори карикатуристи рисуват Туид, опрян на урна, на която пише: 

Ιn Counting There Is Strength („В броенето е силата“). 

Впрочем именно благодарение на вестник The New York Times и на карикатурите на Томас Наст в Harper’s Weekly корупцията на Туид е извадена на показ. Той е обвинен в над 200 престъпления, осъден да лежи 12 години и умира в затвора през 1878 г. „Тамани Хол“ се превръща в нарицателно за политическа корупция.

В броячите е силата. Не, в гражданите
Източник: Wikimedia

Време е да бъде намерено подобно нарицателно и за клептокрацията в България, където партийни мрежи раздават постове, обществени поръчки и услуги срещу лоялност и гласове. 

Гласовете са особено важни, защото осигуряват представителство и власт на партийните мрежи, а в контролираната демокрация осигуряват и привидностите на изборен процес, докато реалната власт остава концентрирана в тесен кръг. Карикатурите и корупционните разкрития не поместват никого в България, защото системата, позволила осъждането на Бос Туид, не работи – тя е фасада, която скрива точно тези мрежи. 

Усърдно помагат и преброителите. А точно те са първата бариера срещу властта на клептократите. Как ще се гласува – с хартиени бюлетини или с машини, е второстепенно, ако хората, които броят гласовете, не са независими, почтени и добре обучени. 

Готовността да се следват правилата осигурява реална легитимност на изборите. 

Дори перфектно разработени технологии не могат да компенсират липсата на етични и компетентни хора в секционните избирателни комисии.

Преброители на къса каишка

В България в ΧΧΙ век изборните бюлетини броят същите хора, които и „Тамани Хол“ е използвала в средата на ΧΙΧ век: партийни активисти; хора на местния „бос“; служители, зависими от партийна благословия (работа, услуги, закрила). И онези „броячи“ отпреди повече от 150 години, и днешните си служат с едни и същи методи: някои бюлетини лесно стават невалидни чрез драсване, неправилно прегъване, зацапване, скъсване на ъгълче и пр.; а други се дописват или направо подменят с предварително попълнени. 

Машинното гласуване не е панацея, но успя значително да намали поне невалидните бюлетини, които през 2017 г. например бяха неприлично много – 169 009, до под 10 000 на вота през 2022 г. Изплашени, партиите от статуквото – ГЕРБ, БСП и ДПС, решиха отново да върнат хартията в играта, свеждайки машините до принтери.

Няма по-голямо доказателство колко много залагат на изборни манипулации от упорството, с което се впускат да променят правилата за гласуване почти преди всеки вот. Машините нарушиха спокойствието на партийния апарат, но не елиминираха заплахата от купен и контролиран вот. А и не биха могли – това е работа на МВР.

При машинното гласуване обаче „броячите“ са безполезни, машините автоматично представят резултатите и контролните разписки. Дочоолу, Гочоолу и останалите аватари на Бос Туид не могат да разпределят най-ценното нещо в една демокрация – гласовете на избирателите, като че са зарзават за консерви. 

Честните избори, ако някой е забравил, са сърцето на демокрацията. 

Нали благодарение на изборите даваме на управляващите правото да вземат решения от името на нас, гражданите? Честният изборен процес е средството, с което избирателите наказват или възнаграждават политиците. 

Диктатурата на „Д“

Колкото по-безобразни са промените, които ГЕРБ–СДС и ДПС – Ново начало подготвят в Изборния кодекс, толкова по-голям е страхът им от срив на предстоящите напролет предсрочни избори. Замисълът, който стана явен тези дни, го потвърждава. Предложените оптични скенери от „хартиената коалиция“ – ГЕРБ, БСП, „Има такъв народ“ и ДПС – Ново начало, захранвани (и) с манипулиран вот, зачеркват машините, защото те им пречат. 

Скенерът отчита с разписка гласуването, след като избирателят е пуснал хартиената си бюлетина. След като се сканира, тя пада в непрозрачна кутия, която се отваря след разпечатването на машинния протокол за отчитане на гласовете. Именно хартиената бюлетина остава оригиналът и при спор се брои ръчно.

На практика скенерите връщат човешкия фактор през задния вход. Макар да се представят като „златната среда“ между хартия и машина, реално запазват контрола на партийните мрежи върху броенето. Технология има, но властта остава при „броячите“.

Помним как на предишните избори в град Белица членка на секционната избирателна комисия гласува вместо избирателите. Пред всички тя попълва празни бюлетини и ги разпределя за две политически сили – ГЕРБ–СДС и ДПС – Ново начало. От 2015 г. община Белица се управлява от най-любимия и верен кмет на олигарха Пеевски – Радослав Ревански. 

Нали никой не си представя, че администрацията на община, управлявана от една политическа сила, няма да нагласи гласове в нейна полза? Всъщност най-големият позор е, че наистина никой не си го представя…

Конституционният съд (КС) обаче намери достатъчно основания да отмени избора на 16 депутати в 51-вия парламент заради сигналите за честността на вота и в резултат на това в Народното събрание влезе и деветата политическа сила – „Величие“. Проверката на КС разкри, че бюлетините в седем секции са изчезнали, въпреки че трябва да се пазят. 

Какво ли би станало, ако бяха проверени всички изборни секции, остана въпрос на догадки и хипотези.

Когато и да е замислила блокирането на опитите за честни избори, властта в оставка изглежда готова да воюва. Отхвърли предложението на ПП–ДБ за 100% машинен вот, подкрепено и от останалата опозиция в парламента, както и от президента, при това изчаквайки да отмине протестът, призовал отново за гласуване с машини.

Честни избори ще отмият в канавката две от партиите – БСП и ИТН, и със сигурност ще ударят по резултатите на ГЕРБ–СДС и ДПС – Ново начало. Онова, с което „броячите“ няма да могат да се справят, е висока избирателна активност и ефективни действия на МВР преди и в деня на вота. Първото зависи от гражданската позиция на избирателите, второто – от служебния премиер. Време е политическите машини за избори да бъдат разглобени и унищожени.

Какво става в Сърбия? Непредвидимото бъдеще

Post Syndicated from Джорджа Спадони original https://www.toest.bg/kakvo-stava-v-surbiya-nepredvidimoto-budeshte/

Какво става в Сърбия? Непредвидимото бъдеще

Белградското утринно небе виси над нас сиво, облачно, тежко. Подухва лек вятър, неочаквано студен за началото на октомври. Но за нашата група италианци това не е проблем, любопитството ги води. Искат да разберат повече за сегашното положение в Сърбия, както и за миналото. Тече третият им ден в столицата и с всяко наше обяснение нещата се преплитат и стават все по-сложни, но те не се предават.

Вървим по скрита уличка в централен квартал на града – от едната ни страна се извисяват величествените правителствени сгради от миналия век, от другата са се наредили по-скромни кооперации. Спираме близо до едно триетажно жълтеникаво здание. Гледаме го отзад. Насочваме вниманието на нашите гости към един от прозорците на последния етаж. Получаваме въпросителни погледи – цялата постройка всъщност изглежда доста незначителна.

„От този прозорец в късната сутрин на 12 март 2003 г. снайперист стреля и убива Зоран Джинджич, докато той влиза през служебния вход на сградата отсреща.“

Групата се заковава на място, внезапно замлъква. Погледите блуждаят между двете сгради. Макар вече да сме им разказали историята за убийството на Джинджич, когато бяхме на гробището, друго е да видиш точното място със собствените си очи. Някой пита колегата ми дали още помни този ден.

„Всеки сърбин, който е бил достатъчно възрастен тогава, си спомня точно къде се е намирал и какво е правил в онази мартенска сутрин, когато е получил новината. Това е нашият 11 септември. Денят, в който всеки от нас разбра, че вратите на света около нас, едва открехнати, отново се затварят. И че пак пропускаме възможността за нормално развитие на тази държава.“

Имало е охрана, да. Имало е и вариант да се влиза с кола в специален тунел за повече безопасност. Но Джинджич не е искал, макар че е бил с патерици, защото се е контузил, докато е играл футбол. И не е първият опит за покушение срещу него, не – отговаряме на гостите. Три седмици преди онзи 12 март камион се опитва безуспешно да се вреже в автоконвоя му.

Случаят „Джинджич“

Още като студент в Белград Зоран Джинджич показва прагматично мислене, политическа интуиция, нюх за духа на времето и ораторски талант. През 70-те години е изхвърлен от университета и по-късно арестуван и осъден за организирането на независимо студентско движение. Емигрира във Федерална република Германия, където през 1979 г. защитава докторат по философия.

Когато се връща в Югославия през 1989 г., с други интелектуалци и активисти основава Демократическата партия (Demokratska stranka). Една година по-късно става неин ръководител и депутат от опозицията, макар мнението му по вечните въпроси на сръбския национализъм да е понякога неясно (през 1994 г. например посещава в Пале президента на Република Сръбска Радован Караджич, за да „изрази своята солидарност със сърбите от Босна“).

През 90-те Джинджич се отличава като ключова фигура в протестите срещу режима на Слободан Милошевич. През 1997 г. опозиционната коалиция Zajedno, в която е и Демократическата партия, се разпада след бойкот на изборите през декември и от други демократични групи. Избухването на войната в Косово през 1998 г. и бомбардировките на НАТО над Сърбия през 1999 г. бележат началото на края за Милошевич. В същото време обаче започва серия убийства, над които пада сянката на президента – от журналиста Славко Чурувия до министъра на отбраната Павле Булатович, от паравоенния командир Желко Ражнатович – Аркан до бившия президент Иван Стамболич.

През септември 2000 г. улиците на страната отново са изпълнени с протестиращи, след като не е призната победата на президентските избори на кандидата на демократичната опозиционна коалиция (Demokratska Opozicija Srbije) Воислав Кощуница. След седмица масови протести на 5 октомври 2000 г. Милошевич подава оставка. Парламентарните избори през декември са спечелени от Демократическата партия с 64,7%. На 25 януари 2001 г. Джинджич става министър-председател – надеждата за промяна се разпростира из страната, окрилена от очакванията от чужбина.

Какво става в Сърбия? Непредвидимото бъдеще
Агитационни материали на различни сръбски партии и политически фигури, явявали се на избори между 1990 и 2000 г © Джорджа Спадони

Правителството на Джинджич започва с амбициозна програма, в която са планирани серия дълбоки и смели икономически и съдебни реформи, както и наказателно преследване за политическите убийства и военните престъпления, специална комисия за разследване на дейността на полицията и тайните служби, сътрудничество с международната общност, решаване на Косовския въпрос. По време на неговия мандат се ратифицира Европейската конвенция за правата на човека и се въвеждат препоръките на Съвета на Европа, което води и до присъединяването на Сърбия и Черна гора към организацията през 2003 г.

Но докато на международно ниво Зоран Джинджич създава положителен имидж, в Сърбия е все по-противоречиво приеман от определени слоеве на обществото и от институциите. Първоначално той е против екстрадицията на Слободан Милошевич в Хага, но през април 2001 г. изиграва ключова роля в ареста му от югославските власти. На 28 юни обаче, въпреки възраженията на Конституционния съд, Джинджич разпорежда екстрадицията на бившия президент в Нидерландия под натиска на САЩ, които заплашват да не отпуснат планираната икономическа помощ от Световната банка и Международния валутен фонд.

Въпреки това Зоран Джинджич не е убит заради неприязънта на националистите. Онзи единствен куршум, пронизал го право в сърцето, е изстрелян от Звездан Йованович, член на „Червените барети“, водещи началото си от Сръбската доброволческа гвардия и по-късно влели се в специалните сили на Службата за държавна сигурност на Сърбия.

Джинджич е убит заради твърдото си намерение да се бори срещу Земунския клан – една от най-мощните престъпни организации в държавата. Същата, която още от 90-те е в тесни връзки със сръбската власт и с чиито представители самият Джинджич се вижда дни преди оставката на Милошевич, получавайки гаранции, че техните формирования няма да пречат на прехода. А мафията, както знаем, е държава в държавата. Това е напълно съзнателна сделка с наследството на Милошевич, пуснало пипалата си навсякъде.

Убийството на Зоран Джинджич е планирано в заговор между тайните служби, организираната престъпност и част от политическите фигури, останали след Милошевич.

Месец преди смъртта му тогавашната главна прокурорка на Хагския трибунал Карла дел Понте се среща с него: 

Разказа ми [Зоран Джинджич – бел. ред.] в подробности за реформаторската си програма. И тогава изведнъж ми каза: „Ще ме убият.“ 

На въпроса ѝ кой по-точно ще го убие, Джинджич отговорил с опасението, че планираните реформи в армията и полицията ще го изложат на опасност.

Джинджич ми обясни как възнамерява да се намеси в армията и полицията, след като е променил икономическата система. Реформата изискваше да се пипа изключително внимателно и беше доста опасна. И министър-председателят беше напълно наясно с това.

Ето как историчката Дубравка Стоянович анализира случилото се в своя статия, публикувана 10 години след убийството на Зоран Джинджич:

Налице бяха и заговорниците във висшите ешелони на тайните служби, които участваха и в предишния преврат – от 2000 г., и благодарение на това имаха особено положение. Налице беше и държавата, подчинена на партийни интереси. И политическата култура, която вижда в опонента враг. И ценностната система, която в компромиса вижда слабост, а в силата – юначество. И интересите на могъщи кръгове, които възприемат изграждането на правова система и институции като пречка за своя монопол.

Може би налице беше и намесата на Великите сили. И преди всичко – същото онова разделение на модернисти и антимодернисти, про- и анти-Запад, което е основната причина за повечето атентати в сръбската история. Ето защо убийството от 2003 г. доказва, че има приемственост, произтичаща от дълбоките проблеми в новата история на Сърбия: слабостта на институциите, мощта на „неконтролираните фактори“, олигархично-партийната държава и нерешения ключов въпрос „А сега накъде?“. 

И като се взираме в днешното положение в страната след още десет години (а и повече), не само че хич не изглежда по-светло, но и не е толкова различно.

Какво става в Сърбия? Езикът на протестите – музика и архитектура
Джорджа Спадони е на обиколка из Белград с нова група туристи, на които разказва за музиката и архитектурата на града, а през този разказ – и на нас за случващото се в Сърбия. Това е втора част от поредицата, посветена на годишнината от трагедията в Нови Сад и на протестите за промяна.
Какво става в Сърбия? Непредвидимото бъдеще

Демокрация или стабилокрация

9 август 2024 г. Чакаме на границата между Босна и Сърбия. Обиколката ни е към края си, прибираме се в Белград, или поне се опитваме. Опашката е безкрайна, безмилостното лятно слънце превръща микробуса в печка, климатикът е почти безпомощен. Групата шумно решава кръстословици, а с колегата ми и шофьора говорим за масовите протести, предвидени в столицата за следващия ден – 10 август.

Бетонната козирка на гарата в Нови Сад, официално открита преди месец, ще издържи още малко. Причината за протеста е друга – проектът за най-голямата литиева мина в Европа, която англо-австралийската компания „Рио Тинто“ възнамерява да разработва в Лозница, до река Ядар, в западната част на страната. Спрян благодарение на огромните протести през 2022 г., планът отново е върнат на дневен ред от сръбското правителство през юли 2024 г. С подкрепата на ЕС.

Най-накрая излизаме от Босна, но не и преди да сме подарили шоколадово блокче на полицая, който, след като ни провери документите, изрично ни поиска такъв странен и сладък подкуп. Влизаме в Сърбия и минаваме точно през местността, застрашена от минните амбиции. Няколко метра след границата ни приветства огромен плакат на управляващата Сръбска прогресивна партия (СПП, Srpska napredna stranka), от който ни гледа мъж с очила и дебели устни. Шофьорът и колегата ми не се въздържат и отправят немалко псувни към този лик, който всъщност принадлежи на Александър Вучич – главния герой в сръбската политика от повече от десетилетие.

Роден е през 1970 г. в Белград и на 23 години се присъединява към Сръбската радикална партия (СРП, Srpska radikalna stranka) – ултранационалистическа формация, която иска да създаде „Велика Сърбия“ от руините на Югославия. Той става протеже на партийния лидер Воислав Шешел, осъден за военни престъпления в Хага. През 1998 г. Вучич е назначен от самия Слободан Милошевич за министър на информацията, като само за две години успява да приложи едно от най-репресивните законодателства в Европа срещу медиите и свободата на словото.

След 5 октомври 2000 г., когато Милошевич подава оставка, СРП е в опозиция, докато се редуват белязани от скандали демократични правителства, които включват присъединяването към ЕС в своите програми. Точно покрай въпроса за ЕС СРП се разделя и част от членовете ѝ начело с Томислав Николич и Александър Вучич я напускат, за да създадат Сръбската прогресивна партия (СПП) през 2008 г. Въпреки името и декларираните проевропейски настроения формацията е силно консервативна и популистка и бързо се превръща в основната опозиционна сила. На парламентарните избори през 2012 г. СПП печели 25% от гласовете и се класира на първо място. Вучич е първо министър на отбраната, а после – вицепремиер. На предсрочните парламентарни избори през 2014 г. СПП удвоява подкрепата си до почти 50% и печели мнозинство в парламента. Тогава Вучич става министър-председател.

Междувременно той признава в интервю „грешките от младостта“ и се отдалечава от националистическите уклони отпреди години, когато публично защитава Ратко Младич и Радован Караджич. Сред амбициите му за Сърбия е присъединяването към ЕС. Всъщност, въпреки че либералните партии, предшестващи СПП, полагат основите на европейските стремежи на Сърбия, именно Вучич дава официален старт на процеса през 2014 г. Следващите предсрочни избори през 2016 г. са предизвикани от СПП точно с цел подкрепа за продължаване и успешно приключване на процеса по кандидатстване за членство в ЕС. Този път СПП събира над 50%, но опозицията заявява, че гласовете са били купени.

В чужбина обаче се повишава задоволството от стабилността, която Сърбия най-накрая демонстрира. Особено в Германия. В интервю от 2016 г. Вучич казва, че смята Ангела Меркел „за истинския лидер на Европа“ и че германската канцлерка „се грижи за Балканите“. Критиците на управлението обаче посочват, че привидната стабилност в страната е постигната за сметка на демократичните ценности, особено на медийната свобода.

Какво става в Сърбия? Непредвидимото бъдеще
Александър Вучич по време на посещение в Москва през 2017 г. Източник: Wikimedia

Изборите през 2017 г., с които Вучич започва своята кариера като президент на Република Сърбия, също са белязани с все по-строг контрол върху медиите и постепенно разрушаване на върховенството на закона. Междувременно, за да продължи да гради „прогресивен“ имидж за пред международната общност, президентът назначава за министър-председател Ана Бърнабич – първата жена на този пост в Сърбия, и то открита лесбийка. Без това да означава, че в програмата на правителството има място за правата на ЛГБТ, напротив – ролята на Бърнабич ѝ осигурява редица привилегии, от които останалата част от ЛГБТ хората в страната е лишена. 

Какво става в Сърбия? Непредвидимото бъдеще
Ана Бърнабич. Източник: Wikimedia

През 2020 г. неправителствената организация „Фрийдъм Хаус“ потвърждава влошаването на положението в балканската страна, която вече не е демокрация, а хибриден режим, особено след резултатите от новите президентски избори през юли, които СПП печели с над 60%. Тази авторитарна тенденция, започнала през 2012 г., превръща държавата в стабилокрация, която въпреки реториката на правителството не е гарант за стабилността в Балканския регион, както вече стана ясно от нестихващите протести, започнали през 2024 г.

Сърбия вън от ЕС, ЕС вън от Сърбия

10 август 2024 г. Обиколката приключва, изпращаме гостите преди началото на протестите, предвидено за 19:00. Тръгваме около час по-рано и улиците вече се пълнят с хора, които се изливат от всички страни. В рамките на половин час центърът на Белград е изцяло блокиран – граждани от всички възрасти, с кучета и детски колички, с плакати и свирки са се събрали с мирни намерения и лошо настроение. Сред слоганите се чете „Рио Тинто марш от Сърбия“, „Няма да копаете“, „ЕС диктува, Вучич изпълнява, Рио Тинто печели“. Колегата ми казва: 

„Виждаш ли колко много хора, всички сме против Вучич от години, излизаме по улиците непрекъснато, но той не мръдва. Защото има подкрепа от ЕС.“

Всъщност тактиката на президента на международно ниво е да поддържа добри отношения с конкурентни геополитически сили. Твърди, че иска Сърбия да продължи своя европейски път, но в същото време поддържа приятелски отношения с Русия и привлича в страната най-големия брой китайски проекти в Европа в рамките на глобалната китайска стратегия за сътрудничество „Един пояс – един път“. В резултат на това, от една страна, отказва да подкрепи санкциите срещу Москва след избухването на войната в Украйна, въпреки че Сърбия има статус на кандидат-членка на ЕС; от друга, възлага все повече поръчки без конкурс на спорни китайски компании.

Една година след трагедията в Нови Сад. Какво става в Сърбия?
На 1 ноември се навършва една година от трагедията в Нови Сад, която провокира някои от най-големите протести в Сърбия, а и в региона ни. Италианката Джорджа Спадони, която обича и познава Балканите, ни разказва в няколко поредни материала как изглеждат Белград и цялата страна година по-късно.
Какво става в Сърбия? Непредвидимото бъдеще

Вярно е, че точно както Бойко Борисов в България, и Александър Вучич има подкрепа от ЕС, с който освен това се осъществява над половината от търговията на Сърбия. Но за разлика от България, присъединителният процес в Сърбия отдавна е в бюрократична парализа, от която се възползва правителството на Вучич. А междувременно Европейският съюз вече не е синоним на прогрес и гаранции, а по-скоро представлява някакво далечно и абстрактно образувание, което постоянно се доказва като все по-лицемерно и индиферентно спрямо непрекъснатото западане на демокрацията и принципите на правовата държава в Сърбия.

Сред последните удари по доверието към Съюза е откровеното насърчаване на проекта на „Рио Тинто“ в Лозница, който даже е представен като стратегически проект на ЕС през 2025 г. Освен това слабата реакция от Брюксел спрямо мащабната вълна от антиправителствени протести, провокирана от трагедията в Нови Сад, играе важна роля в спада на доверието на сърбите към ЕС.

През октомври 2025 г. Европейският парламент прие резолюция, призоваваща за правото на мирни протести в Сърбия и изискваща политическа отговорност за засилените репресии. Ефективността на тези призиви обаче е доста ограничена и е застрашена от все по-влиятелната крайна десница, която подкрепя Вучич. Един месец по-късно „Рио Тинто“ обяви, че проектът „Ядар“ ще бъде поставен в режим „грижа и поддръжка“ поради липса на разрешителни и напредък, както и заради силна местна съпротива. Но това вероятно няма да е краят на историята и е все по-трудно да се предвиди какво крие бъдещето за балканската държава.

Какво става в Сърбия? Непредвидимото бъдеще
16 минути мълчание за 16-те жертви от трагедията в Нови Сад година по-късно © Джорджа Спадони

2025 г. Ден преди да покажем на туристическата група мястото, където е убит министър-председателят, се събираме около неговата паметна плоча на гробищата. Над черния мрамор, под надписа „Д-р Зоран Джинджич 1952–2003“, намираме леко повехнал венец от цветя, завързан с лента. Вятърът я е обърнал. Навеждам се и я премествам, за да видя дали пише нещо. Само едно кратко изречение: Hvala za viziju („Благодарим за визията“).

Срещу входа на Философския факултет в Белград – мястото, откъдето всеки път започваме нашите обиколки – погледът на бившия първи министър, напръскан с червена боя, все още се взира в студентите и минувачите. До неговото лице все още може да се разчете излющеното Gledajte u budućnost… („Гледайте в бъдещето…“) – колкото и мътно и страшно да изглежда. Защото друга опция няма.

Т.Е. от Е.Т. – епизод 37

Post Syndicated from Тоест original https://www.toest.bg/t-e-ot-e-t-epizod-37/

Т.Е. от Е.Т. – епизод 37

Навлизаме в новата година плавно и полека с включвания от Доналд Тръмп, Бойко Борисов, Слави Трифонов и други симпатяги.


Следете видеорубриката на Елена Телбис за „Тоест“ и във Facebook, Instagram и TikTok.

From deployment slop to production reality: How BriX bridges the gap with enterprise-grade AI infrastructure

Post Syndicated from Grab Tech original https://engineering.grab.com/brix

Abstract

You’ve vibe-coded an AI assistant that’s a game-changer for your team. It works perfectly on your laptop. But when you try to deploy it company-wide, everything falls apart.

This is what is known as “deployment slop”—the messy reality when quick AI prototypes hit the enterprise world. Your tool suddenly becomes unreliable, insecure, and impossible to maintain. Different teams run different versions. Security flags it. IT won’t touch it. Your innovation dies.

BriX solves this. It’s a platform that takes your working AI prototype and makes it production-ready—without forcing you to become a full-stack developer. BriX handles the hard parts such as security, scaling, and data connections, so you can focus on building great tools. Switch between AI models like Claude or GPT with a click. Connect securely to your company’s data sources. Deploy once, and it just works—for everyone.

This article shows how BriX transforms AI deployment from an engineering bottleneck into a configuration task, enabling domain experts to ship enterprise-grade AI tools in days instead of months.

Introduction

Building AI tools has never been easier. With ChatGPT, Claude, and other Large Language Models (LLMs), anyone can prototype a useful AI assistant in an afternoon. Data analysts build metric query tools; product managers create research assistants. This rapid experimentation—”vibe coding”—has sparked innovation across organizations.

But then comes the hard part: deployment.

That brilliant tool you built on your laptop? It works great for you. But when your boss asks you to “roll it out to the whole company,” you hit a wall. Suddenly you need:

  • Security reviews (Is it leaking sensitive data?)
  • Reliability guarantees (What happens when 500 people use it at once?)
  • Access controls (Who can see what data?)
  • Audit trails (Who asked what, and when?)
  • Consistent behavior (Why does it give different answers to different people?)

Most builders aren’t DevOps engineers. They’re domain experts who had a good idea. So these tools either:

  • Never get deployed (innovation dies in a Jupyter notebook); or
  • Get deployed badly (creating “Deployment Slop”—a mess of insecure, unreliable scripts).

The three failure modes of deployment slop

The chaos problem: Everyone’s running a different version

Marketing copies your script and tweaks the prompts. Finance changed the model from GPT-4 to Claude because it’s cheaper. Sales adds their own data sources. Within weeks, you have:

  • Five different versions of “the same tool”.
  • Wildly different answers to the same question.
  • No one knows which version is “correct”.
  • Teams making decisions based on inconsistent data.

Potential risk: A senior executive receiving conflicting answers from different teams, resulting in a loss of trust.

The reliability problem: It works until it doesn’t

Your laptop script was built for one user (you). Now 50 people are using it simultaneously. The result:

  • Timeouts and crashes during peak hours.
  • No error handling (users see cryptic Python stack traces).
  • Rate limits hit on API calls.
  • No monitoring or alerts when things break.
  • You become the “on-call” support person for a side project.

Potential risk: The tool fails during a critical metric review leaving folks to find the solution manually.

The security problem: Accidental data leaks

Your prototype connects directly to production databases. It has your personal credentials hardcoded. There’s no:

  • Access control (everyone sees all data, including sensitive info).
  • Audit trail (no record of who queried what).
  • Data governance (PII might be exposed).
  • Compliance review (legal and security teams don’t even know it exists).

Potential risk: An employee inadvertently querying PII, resulting in a potential breach.

Who gets hit hardest?

This problem is especially painful for semi-technical builders—the domain experts who understand the business problem but aren’t DevOps engineers:

  • Product Managers who write SQL but not Kubernetes configs.
  • Data Analysts who know Python but not cloud security.
  • Marketing Ops who build dashboards but not CI/CD pipelines.
  • HR Analytics who understand people data but not infrastructure scaling.

The traditional solution is to “hand it to Engineering,” but they are backlogged for months. By the time they rebuild your tool “properly,” the business need has changed.

Solution: Enter BriX: From prototype to production in days, not months

BriX is a platform that solves the deployment problem by centralizing all the hard infrastructure work. Instead of forcing every builder to become a DevOps expert, BriX provides the production-ready foundation so you can focus on building great AI tools.

The core insight: Deployment doesn’t have to be an engineering problem. It can be a configuration problem.

What BriX does

Think of BriX as the “production layer” for AI tools. You bring your working prototype. BriX handles security, scaling, data connections, monitoring, audit trails, and consistent behavior across teams.

You configure. BriX deploys.

Figure 1. BriX infrastructure

The three core capabilities

Choose your AI model (Model agnosticism)

Different tasks need different models. BriX lets you switch between models with a dropdown—Claude, GPT, Gemini, or others. Test which works best. Change models without rewriting code. Optimize for cost vs. performance.

Example: Your finance tool uses GPT-4 for complex analysis, but a new better model is available. Change it in BriX with one click—no code changes needed.

Figure 2. Model selection interface

Connect to enterprise data securely (Model Context Protocols)

This is where BriX really shines. Your AI tool needs data—metrics, customer info, documentation. But connecting to enterprise systems securely is hard.

Model Context Protocols (MCPs) are BriX’s solution. Think of them as secure, pre-built connectors to your company’s data sources.

Why MCPs matter:

  • Security built-in: No hardcoded credentials, proper access controls.
  • Certified data: Connect only to approved, governed data sources.
  • No custom integration: Pre-built connectors, not custom API code.
  • Audit trails: Every query is logged automatically.

Example: Your marketing tool can query the metrics system to get conversion rates, search the knowledge base for campaign guidelines, and pull customer data from the data lake —all through secure, governed connections.

Technical note: MCPs use a standardized protocol, so adding new data sources doesn’t require rebuilding your tool. BriX handles the complexity.

Figure 3. BriX chat user interface

Ensure consistent behavior (System prompts and context)

Remember the “chaos problem” where everyone runs different versions? BriX solves this with centralized configurations by allowing you to lock it down for the users:

  • System prompts: Define your AI’s personality, tone, and guardrails once.
  • Context files: Upload reference documents that every instance uses.
  • Global enforcement: All users get the same behavior automatically.

Example: Your customer support tool has a system prompt that says “Always be empathetic, never make promises about refunds, escalate to humans for complaints.” Every support agent’s AI follows these rules—no exceptions.


Figure 4. The builder’s view

Additional feature: Flexible interfaces and collaboration

Beyond the core infrastructure, BriX offers flexible ways to consume these tools. BriX goes beyond conversational interfaces—you can host custom UIs built with any frontend framework while BriX handles the AI backend. Users can also generate and share analyses as persistent reports, turning individual queries into institutional knowledge accessible across teams via shareable links—complete with data, visualizations, and AI insights.

Figure 5. Share feature interface

The BriX workflow: A real example

Let’s see how a product manager would use BriX:

Step 1: Upload your prototype

  • You’ve built a Jupyter notebook that queries metrics and generates reports.
  • Upload it to BriX (or connect your GitHub repo).

Step 2: Configure (Not code)

  • Choose your AI model: Claude 4.5 Sonnet
  • Connect data sources: Midas (metrics), Hubble (data lake)
  • Set system prompt: “You’re a data analyst. Always cite sources. Format numbers with commas.”
  • Upload context: Your company’s metrics definitions guide.

Step 3: Lock

  • Lock all the configurations of your BriX.
  • Share with your team.
Figure 6. BriX landing page

Figure 7. The user’s view (Locks and edit not available)

Step 4: It just works

  • Certification by design with Brick Quality residing with the brick admin.
  • Focused use cases have specific system prompts, context – minimizing hallucination concerns.
  • People can use it simultaneously (BriX handles scaling).
  • Everyone gets consistent answers (same model, same prompts).
  • All queries are logged (audit trail automatic).
  • The security team is happy (proper access controls).
  • You’re not on-call (BriX monitors and alerts).

Time to production: 3 Days, not 3 months.

Under the hood: The BriX architecture

BriX is built on a synchronous streaming architecture—a design that prioritizes real-time responsiveness without sacrificing enterprise security. Think of it like a live sports broadcast: you see the action as it happens, not a delayed replay.

Figure 8. BriX architecture

Here’s how a single user request flows through the system, from question to answer.

The request journey: Six layers

User Question
      ↓
[1] The Frontend — Real-Time Streaming
      ↓
[2] The Gateway — FastAPI Backend
      ↓
[3] The Brain — LangGraph Orchestration
      ↓
[4] Memory — Hot and Cold Storage
      ↓
[5] Security — Identity Propagation ("On-Behalf-Of" Flow)
      ↓
[6] Data Processing — Full Context, Not Fragments
      ↓
Response streams back to user in real-time

Let’s break down each layer.

Layer 1: The frontend — Real-time streaming

  • Technology: React (TypeScript)
  • User experience: ChatGPT-style interface

The User types a question: “What’s our conversion rate in Singapore last month?”

The frontend opens a persistent connection to BriX servers. As the AI processes the question, updates stream back instantly:

  • “🤔 Thinking…”
  • “📊 Querying metrics database…”
  • “✅ Found 3 relevant data points…”
    [Final answer appears]

Why streaming matters:

Traditional approach BriX approach
❌ User waits 30 seconds, sees nothing, then gets full answer (feels broken). ✅ User sees progress every second (feels responsive and trustworthy).

Technical implementation: Server-Sent Events (SSE) for real-time updates without WebSocket complexity.

Layer 2: The Gateway — FastAPI backend

  • Technology: FastAPI (Python)
  • Role: Central traffic controller

What it does:

  • Receives all incoming requests
  • Authenticates users (checks SSO tokens)
  • Routes requests to the appropriate agent
  • Manages rate limiting (prevents abuse)
  • Handles errors gracefully

Why FastAPI?

  • ⚡ Fast (async/await for concurrent requests)
  • 🔒 Secure (built-in authentication)
  • 📈 Scalable (handles thousands of concurrent users)

Layer 3: The Brain — LangGraph orchestration

  • Technology: LangGraph (AI workflow framework)
  • Role: The “main agent” that coordinates everything.

Think of LangGraph as a smart router that understands intent and delegates work.

Example flow:

User asks: “Compare our Singapore and Malaysia conversion rates, then explain why they differ”.

LangGraph analyzes the question:

  • Task 1: Query metrics (needs Midas MCP)
  • Task 2: Compare data (needs calculation)
  • Task 3: Explain differences (needs context/knowledge base)

LangGraph delegates to specialized “MCPs”:

  • Midas MCP: Queries Midas for conversion data
  • LLM Agent: Calculates the difference
  • Glean MCP: Searches knowledge base for regional factors

LangGraph synthesizes: Combines results into coherent answer
Why modular “Bricks”?

  • ✅ Reliability: Each Brick is specialized (fewer hallucinations)
  • ✅ Maintainability: Update one Brick without breaking others
  • ✅ Extensibility: Add new Bricks for new use cases

Layer 4: Memory — Hot and cold storage

BriX uses a two-tier memory system to balance speed and durability:

Hot memory (Redis):

  • ⚡ Ultra-fast: In-memory storage (microsecond access).
  • 🔄 Session management: Tracks active conversations.
  • 🔒 Distributed locks: Prevents race conditions when multiple requests happen simultaneously.
  • 💨 Temporary: Data expires after session ends.

Cold memory (PostgreSQL):

  • 💾 Persistent: Data stored permanently
  • 📜 Audit trail: Every query, response, and action logged
  • 🔍 Searchable: Users can search past conversations
  • 📊 Analytics: Track usage patterns and performance

Example scenario:

  • You ask BriX a question → Hot memory tracks your active session
  • You close the browser → Session data moves to cold memory
  • You return tomorrow → BriX loads your history from cold memory
  • You continue the conversation → New session in hot memory

Result: Fast responses + complete history + full auditability

Layer 5: Security — Identity propagation (“On-Behalf-Of” flow)

This is where BriX’s security model shines. Instead of using a single “service account” to access all data, BriX uses your credentials for every query.

How it works:

Step 1: Authentication (Login)

  • You log in via SSO (e.g., Okta, Azure AD)
  • BriX receives a secure token that represents your identity
  • This token includes your permissions (what data you can access)

Step 2: Identity propagation (Query execution)

  • You ask: “Show me customer revenue data”
  • BriX doesn’t use its own credentials to query the database
  • Instead, BriX carries your token to the data source
  • The data source checks: “Does this user have permission to see revenue data?”
    • If yes → Returns data
    • If no → Access denied

Step 3: Audit trail

  • Every query is logged with:
    • Who asked (your user ID)
    • What they asked (the question)
    • What data was accessed (the query)
    • When it happened (timestamp)

Why this matters:

Traditional approach BriX approach
❌ Service account has access to ALL data. ✅ Each user only sees their authorized data.
❌ Can’t tell who accessed what. ✅ Complete audit trail per user.
❌ Security team nervous about AI tools. ✅ Security team approves (same controls as existing tools).
❌ One compromised credential = full breach. ✅ Breach limited to single user’s permissions.

Real-world example:

  • Finance analyst asks about revenue → Sees all financial data (authorized)
  • Marketing analyst asks same question → Sees only marketing budget (restricted)
  • Same AI tool, different permissions → Security enforced automatically

Technical term: This is called “identity propagation” or “on-behalf-of flow” in enterprise security.

Layer 6: Data processing — Full context, not fragments

The old way (Retrieval Augmented Generation (RAG)):

  1. User asks a question.
  2. System searches for relevant document chunks.
  3. System sends top 5 chunks to AI.
  4. AI answers based on fragments.

Problem: AI might miss context from other parts of the document.

The BriX way (Full context):

  1. User uploads a document.
  2. BriX feeds the entire document into the AI’s context window.
  3. AI reads and understands the full document.
  4. AI answers with complete context.

Why this works now: Modern AI models (Claude, GPT-4) have massive context windows (100K+ tokens). They can process entire documents, not just snippets—resulting in more accurate answers and fewer hallucinations.

Example:

Question: “What’s our refund policy for international orders?”

  • RAG approach: Finds 3 snippets about refunds → Might miss international-specific rules
  • BriX approach: Reads entire policy document → Finds exact international refund section

Architecture summary: Why this design works

Design choice Benefit User impact
Streaming architecture Real-time feedback Feels fast and responsive
Modular Bricks Specialized agents Fewer errors, more reliable
Hot/Cold memory Speed + durability Fast responses + full history
Identity propagation User-level security Only see authorized data
Full context processing Complete understanding More accurate answers

The result: An AI platform that feels as fast as ChatGPT but with enterprise-grade security and reliability.

What using BriX actually feels like

All the technical architecture is invisible to end users. Here’s what they actually see and experience.

Login: One click, no new passwords

What users see:

  • Visit BriX URL
  • Click “Log in with SSO” (uses your existing company login)
  • Redirects to familiar authentication screen
  • Logged in automatically

What users DON’T see:

  • No new account creation
  • No password to remember
  • No security questionnaire
  • BriX inherits your existing permissions automatically

Why this matters: Zero onboarding friction. If you can access your email, you can use BriX.

The app library: Your company’s AI tools

What users see: Company’s internal “App Store” for AI tools.

  • Each tool is pre-configured and vetted
  • Click to launch (no installation)
  • Tools are tailored to company’s data and processes

Using a Tool: ChatGPT-style interface

What users see:
See the AI “thinking” and “querying”—no black box waiting. Builds trust (“I can see it’s actually checking the data”).

Source citations:
Every answer includes a data source. Click to view original data. No “trust me” answers.

Conversational follow-ups:
“Why did it increase?” | “Compare to Malaysia” | “Show me a chart”

BriX remembers the context.

Data upload: Drag, drop, analyze

What users have:

  • Files are processed securely (encrypted).
  • AI reads the full content.
  • Users can ask questions about the files.
  • Files are only visible to the uploader (privacy).

Trustworthy answers: Certified data, not hallucinations

The problem BriX solves:

ChatGPT/Generic AI BriX
❌ Makes up data (“hallucinations”) ✅ Only uses your company’s real data
❌ No source citations ✅ Every answer cites the source
❌ Can’t access internal data ✅ Connects to your data lakes, metrics, docs
❌ Same answer for everyone ✅ Respects your permissions (you only see your data)

Why users trust it:

  • ✅ Specific number (not vague)
  • ✅ Source cited (can verify)
  • ✅ Certified data (governance approved)
  • ✅ Timestamp (know it’s current)
  • ✅ Can export/verify (transparency)

The impact: What BriX actually changes

BriX shifts how organizations build AI tools. Here’s what that looks like in practice.

From months to days

Traditional path BriX path
1. Domain expert has idea. 1. Domain expert has idea
2. Submits request to engineering. 2. Configures the idea in BriX.
3. Waits in backlog (weeks to months). 3. Tests with small group.
4. Engineering rebuilds it “properly”. 4. Deploys to production.
5. Tool finally launches. 5. Shares with team.

What changes:

  • ⚡ Speed (hours instead of months)
  • 👤 Ownership (domain experts maintain their tools)
  • 🔄 Iteration (refine based on feedback immediately)
  • ✅ Success rate (ideas get tested instead of dying in backlog)

True democratization

Who builds tools with BriX:

The shift isn’t just engineers anymore. We’re seeing:

  • Product managers building feature analysis tools.
  • Data analysts creating custom dashboards.
  • Marketing ops building campaign trackers.
  • Sales ops creating pipeline monitors.
  • HR analytics building retention tools.

What this means:

Domain expertise stays with domain experts (no translation loss). Engineering focuses on platforms (not individual tool requests). Innovation happens at business speed (not constrained by engineering capacity).

The reality check:

Not every domain expert will build tools (and that’s fine). Some tools still need engineering (complex integrations, custom logic). But the bottleneck shifts from “engineering capacity” to “good ideas.”

Flexibility without fragility

What you can change without rewriting code:

Swap AI models:

  • Dropdown menu selection (GPT-5, Claude, Gemini)
  • Different teams can setup different models for their BriX
  • Can test new models without rebuilding tools

Add data sources:

  • New MCP connector (one-time setup)
  • All existing tools can access the new source
  • No need to update individual tools

Update behavior globally:

  • Change system prompt in one place
  • All instances follow new rules immediately
  • Useful for policy updates, compliance changes

Real example: When a company needs to update data access policies:

  • Traditional approach: Update each tool individually (days/weeks)
  • BriX approach: Update system prompt once (minutes)

Security that enables (Not blocks)

The traditional trade-off:

  • Secure tools = slow approval, limited functionality
  • Fast tools = security nightmares, compliance issues

BriX’s approach: Security is built into the platform, not added per tool.

What’s automatic:

  • SSO authentication (no passwords to manage)
  • Identity propagation (users see only their authorized data)
  • Audit logging (every query tracked)

What this changes:

  • Security team reviews the platform once (not every tool)
  • Builders don’t need to become security experts
  • Compliance is automatic (audit trails, access controls)
  • Tools can move fast without sacrificing governance

Real impact: Security teams that previously rejected most AI proposals can pre-approve BriX. Then tools built on BriX inherit those security controls automatically.

BriX will:

  • Provide infrastructure for rapid AI tool deployment.
  • Make it easier for domain experts to productionize ideas.
  • Centralize security and governance.
  • Reduce (not eliminate) the engineering bottleneck.
  • Give you a path from prototype to production.

The real impact

The biggest change isn’t technical. It’s organizational.

BriX changes the conversation from:

“Can engineering build this for us?”

to:

“Let me try building this and see if it works”

That shift—from asking permission to testing ideas—is the real impact.
Some ideas will fail. That’s fine. The cost of testing is now low enough that failure is acceptable.

The ideas that succeed can scale immediately. That’s what matters.

Adoption: From zero to production reality

This isn’t theoretical. Real teams are using BriX right now:

  • The Universal Playground – Data analysts and product managers drop in to run quick analyses or ask questions—no setup, no credentials to configure. Just connect and go. It’s become the default “let me check something” tool.
  • Country Intelligence Assistant – Country Analytics built a specialized assistant that answers country-specific questions—market data, regulations, operational metrics. It’s now the go-to source for regional teams making local decisions.
  • Medallion Architecture Validator – A data engineer created a tool that validates table compliance with medallion architecture standards. What used to take manual reviews now happens instantly. Teams query it before deployments to catch issues early.
  • Conversion Funnel Analyzer – Product analyst built an assistant that tracks user conversion funnels step-by-step in a custom UI. Marketing and product teams use it daily to understand drop-off points without writing SQL.

Learnings/conclusion

The promise: Anyone can build AI tools.
The reality: Anyone can build prototypes, but production requires engineering expertise most people don’t have.

BriX bridges that gap.

What BriX does

For domain experts: Build and own tools without becoming DevOps experts. Iterate in hours, not months.
For engineering: Stop being the bottleneck. Secure the platform once, not every tool.
For the organization: Test more ideas. Scale what works. Automatic security and compliance.

Why BriX works: Three design principles

Building BriX taught us that successful enterprise AI platforms require:

Specialization over generalization
Users prefer 5 focused tools over 1 unpredictable tool. That’s why BriX uses modular “Bricks”—each specialized for specific tasks (data analysis, trend detection, document search). Narrow scope = better reliability.

Enablement over control
Deployment slop isn’t a problem to eliminate—it’s evidence of demand. Don’t kill experimentation; provide the path to production. BriX lets teams experiment locally, then offers the infrastructure to scale what works.

Reliability over features
Users forgive missing features. They don’t forgive unreliability. One slow response or wrong answer = they never come back. That’s why BriX prioritizes real-time streaming, certified data sources, and source citations over adding more capabilities.

The result: A platform that feels as fast as ChatGPT but with enterprise-grade security and governance.

Configure once. Analyze everywhere. Act fast.

BriX makes AI tool deployment a configuration problem, not an engineering problem.

Your domain experts have the ideas. BriX gives them the path to production.

What’s next

BriX solves deployment, but we’re not stopping there.

More data sources

We’re expanding the MCP library. If our company uses it, BriX should connect to it—securely and without custom engineering work.

Bring your own code

For technical builders who want custom logic without DevOps headaches, we’re launching a mono repo setup:

  • App owners own: Their code and business logic
  • BriX owns: Platform, security, scaling, maintenance

More BriX

Onboarding more BriX for different tech and non-tech personas.

Join us

Grab is a leading superapp in Southeast Asia, operating across the deliveries, mobility and digital financial services sectors. Serving over 800 cities in eight Southeast Asian countries, Grab enables millions of people everyday to order food or groceries, send packages, hail a ride or taxi, pay for online purchases or access services such as lending and insurance, all through a single app. Grab was founded in 2012 with the mission to drive Southeast Asia forward by creating economic empowerment for everyone. Grab strives to serve a triple bottom line – we aim to simultaneously deliver financial performance for our shareholders and have a positive social impact, which includes economic empowerment for millions of people in the region, while mitigating our environmental footprint.

Powered by technology and driven by heart, our mission is to drive Southeast Asia forward by creating economic empowerment for everyone. If this mission speaks to you, join our team today!

A 0-click exploit chain for the Pixel 9 (Project Zero)

Post Syndicated from corbet original https://lwn.net/Articles/1054547/

The Project Zero blog has a
three-part series
describing a working, zero-click exploit for
Pixel 9 devices.

Over the past few years, several AI-powered features have been
added to mobile phones that allow users to better search and
understand their messages. One effect of this change is increased
0-click attack surface, as efficient analysis often requires
message media to be decoded before the message is opened by the
user. One such feature is audio transcription. Incoming SMS and RCS
audio attachments received by Google Messages are now automatically
decoded with no user interaction. As a result, audio decoders are
now in the 0-click attack surface of most Android phones.

The blog entry does not question the wisdom of directly exposing audio
decoders to external attackers, but it does provide a lot of detail showing
how it can go wrong. The first part looks at compromising the codec; part
two
extends the exploit to the kernel, and part
three
looks at the implications:

It is alarming that it took 139 days for a vulnerability
exploitable in a 0-click context to get patched on any Android
device, and it took Pixel 54 days longer. The vulnerability was
public for 82 days before it was patched by Pixel.

Amazon EC2 X8i instances powered by custom Intel Xeon 6 processors are generally available for memory-intensive workloads

Post Syndicated from Channy Yun (윤석찬) original https://aws.amazon.com/blogs/aws/amazon-ec2-x8i-instances-powered-by-custom-intel-xeon-6-processors-are-generally-available-for-memory-intensive-workloads/

Since a preview launch at AWS re:Invent 2025, we’re announcing the general availability of new memory-optimized Amazon Elastic Compute Cloud (Amazon EC2) X8i instances. These instances are powered by custom Intel Xeon 6 processors with a sustained all-core turbo frequency of 3.9 GHz, available only on AWS. These SAP certified instances deliver the highest performance and fastest memory bandwidth among comparable Intel processors in the cloud.

X8i instances are ideal for memory-intensive workloads including in-memory databases such as SAP HANA, traditional large-scale databases, data analytics, and electronic design automation (EDA), which require high compute performance and a large memory footprint.

These instances provide 1.5 times more memory capacity (up to 6 TB), and 3.4 times more memory bandwidth compared to previous generation X2i instances. These instances offer up to 43% higher performance compared to X2i instances, with higher gains on some of the real-world workloads. They deliver up to 50% higher SAP Application Performance Standard (SAPS) performance, up to 47% faster PostgreSQL performance, up to 88% faster Memcached performance, and up to 46% faster AI inference performance.

During the preview, customers like RISE with SAP utilized up to 6 TB of memory capacity with 50% higher compute performance compared to X2i instances. This enabled faster transaction processing and improved query response times for SAP HANA workloads. Orion reduced the number of active cores on X8i instances compared to X2idn instances while maintaining performance thresholds, cutting SQL Server licensing costs by 50%.

X8i instances
X8i instances are available in 14 sizes including three larger instance sizes (48xlarge, 64xlarge, and 96xlarge), so you can choose the right size for your application to scale up, and two bare metal sizes (metal-48xl and metal-96xl) to deploy workloads that benefit from direct access to physical resources. X8i instances feature up to 100 Gbps of network bandwidth with support for the Elastic Fabric Adapter (EFA) and up to 80 Gbps of throughput to Amazon Elastic Block Store (Amazon EBS).

Here are the specs for X8i instances:

Instance name vCPUs Memory
(GiB)
Network bandwidth (Gbps) EBS bandwidth (Gbps)
x8i.large 2 32 Up to 12.5 Up to 10
x8i.xlarge 4 64 Up to 12.5 Up to 10
x8i.2xlarge 8 128 Up to 15 Up to 10
x8i.4xlarge 16 256 Up to 15 Up to 10
x8i.8xlarge 32 512 15 10
x8i.12xlarge 48 768 22.5 15
x8i.16xlarge 64 1,024 30 20
x8i.24xlarge 96 1,536 40 30
x8i.32xlarge 128 2,048 50 40
x8i.48xlarge 192 3,072 75 60
x8i.64xlarge 256 4,096 80 70
x8i.96xlarge 384 6,144 100 80
x8i.metal-48xl 192 3,072 75 60
x8i.metal-96xl 384 6,144 100 80

X8i instances support the instance bandwidth configuration (IBC) feature like other eighth-generation instance types, offering flexibility to allocate resources between network and EBS bandwidth. You can scale network or EBS bandwidth by up to 25%, improving database performance, query processing speeds, and logging efficiency. These instances also use sixth-generation AWS Nitro cards, which offload CPU virtualization, storage, and networking functions to dedicated hardware and software, enhancing performance and security for your workloads.

Now available
Amazon EC2 X8i instances are now available in US East (N. Virginia), US East (Ohio), US West (Oregon), and Europe (Frankfurt) AWS Regions. For Regional availability and a future roadmap, search the instance type in the CloudFormation resources tab of AWS Capabilities by Region.

You can purchase these instances as On-Demand Instances, Savings Plan, and Spot Instances. To learn more, visit the Amazon EC2 Pricing page.

Give X8i instances a try in the Amazon EC2 console. To learn more, visit the Amazon EC2 X8i instances page and send feedback to AWS re:Post for EC2 or through your usual AWS Support contacts.

— Channy

The collective thoughts of the interwebz